AI Governance, Practitioner Led

AI moves fast.
Build it safePractitioner-led AI governance and implementation.

A practitioner led governance and implementation practice for boards, regulators, and product leaders adopting AI. We design the controls, then help your teams run them in production, so the posture holds up under audit, procurement, and supervisory review.

Services

Five engagements, one standard.

Built and run by a practitioner who has shipped AI inside regulated environments. The output is implementation, not recommendations on a page.

01

AI Governance Assessment

A four-to-six week diagnostic of your AI estate. System inventory, EU AI Act risk classification, ISO 42001 gap analysis, and a prioritised remediation plan your board, your engineers, and your auditors can all read.

  • AI system register and risk matrix
  • Control gap report with evidence requirements
  • 90-day remediation roadmap
  • Board-ready summary
Learn more →
02

AI Compliance Consulting

EU AI Act, ISO/IEC 42001, NIST AI RMF, and DORA — implemented inside your existing SDLC, MLOps, and risk processes. One set of controls, multiple frameworks reported against.

  • EU AI Act readiness and high-risk obligations
  • ISO 42001 management system and audit prep
  • OWASP LLM and ML threat coverage
  • Audit-ready evidence packs
Learn more →
03

AI Governance Consulting

Strategy, operating model, controls, and ongoing advisory for organisations governing AI in regulated environments. One named practitioner, no rotating juniors, evidence written for your stack.

  • Governance operating model design
  • Control framework and implementation
  • Fractional advisory and board support
  • Vendor and incident response review
Learn more →
04

AI Product Strategy

From use case evaluation to responsible deployment. I sit with product and engineering teams making AI decisions in high-stakes environments, separating signal from theatre and turning intent into roadmaps your risk function can sign off on.

  • Use case prioritisation
  • Build, buy, partner review
  • Launch readiness assessment
05

Workshops & Enablement

Practical sessions for leadership, legal, and engineering teams on AI-first adoption, secure AI practices, and what good governance looks like in the codebase, the pipeline, and the boardroom.

  • Board-level briefings
  • Engineering deep dives on OWASP for LLMs
  • Cross-functional playbooks

Engagements typically run 4 to 12 weeks, scoped to outcome.

Contact for pricing →
Methodology

A four part implementation framework, tuned to your stack and your regulator.

Each engagement follows the same arc, discover, define, document, operate, but the deliverables and depth are scoped to where you are now and what your supervisors expect next.

  1. I

    Map the terrain

    Inventory of AI surfaces in production and pipeline. Risk classification against the regulatory frame that actually applies to you, including EU AI Act, ISO 42001, and DORA where relevant.

  2. II

    Set the line

    Define controls, accountabilities, and decision rights. Aligned with product reality and OWASP threat guidance for LLM and ML systems, not org chart fiction.

  3. III

    Build the evidence

    Documentation, model cards, monitoring, and audit trails. The artefacts you need before a regulator, auditor, or enterprise procurement team asks for them.

  4. IV

    Operate with confidence

    Embed review cadences, escalation paths, and training so governance lives in the workflow, not in a binder. Implementation support runs alongside your teams.

About

Practitioner, not consultant.

Dhvani Puar, founder of Build It Safe

Dhvani Puar

Founder · Build It Safe

I'm Dhvani Puar. I've spent 11 years building and shipping AI-enabled products inside one of the world's most complex regulated environments — Mastercard's global payments network.

Fraud detection, AML transaction monitoring, cybersecurity platforms, biometric authentication, crypto risk. Products processing over a billion transactions. Regulatory obligations across 40+ markets. AI decisions operating under real scrutiny, not just on paper.

Build It Safe is the governance and implementation practice I run for organisations adopting AI without the infrastructure to support it safely. My clients tend to be fintechs and technology companies without a dedicated AI risk or compliance team, navigating regulatory pressure, model risk, or the practical challenge of making AI adoption defensible.

I don't sell frameworks for their own sake. The deliverable is always the same: decisions you can defend, controls your team can actually run, and a governance posture that survives the next audit, model release, or regulatory review.

Based in Dublin, working globally.

EU AI ActISO/IEC 42001NIST AI RMFDORAOWASP for LLMs & MLModel risk managementResponsible AISecure by design
Articles

Field notes from the practice.

Originally published on LinkedIn, collected here for the people who don't live in the feed.

Free download

The AI Governance Starter Pack.

A 14 page brief covering the six questions every regulator asks, the artefacts you should have ready, and a one page board template. Built from real engagements, no sales fluff.

  • · EU AI Act and DORA risk classification cheat sheet
  • · OWASP LLM controls mapping
  • · Board reporting one pager
  • · Inspection readiness checklist

We'll only use your details to send the pack and one short follow-up. No newsletter.

FAQ

Questions I get asked before the first call.

If yours isn't here, send it directly. I read every inquiry.

Ask a question →
  • Boards, CXOs, and senior product or risk leaders inside regulated organisations, including banks, insurers, healthcare, and public sector, plus scale ups selling into them. If your AI deployment will be inspected, audited, or procured against, we're a fit.

  • Neither. I'm a practitioner. I work upstream of legal and audit, designing the product decisions, controls, and evidence, and then helping your teams implement them so those reviews don't become blockers.

  • EU AI Act, ISO/IEC 42001, NIST AI RMF, DORA, OWASP guidance for LLM and ML applications, sectoral guidance (for example EBA, PRA, FDA), and internal model risk frameworks. The framework is a means. The goal is a posture that holds up.

  • I don't hand over a deck and leave. Every engagement ships an implementation: controls deployed, evidence collected, teams trained, and a way to operate the posture after I step out.

  • Most engagements run 4 to 12 weeks against a defined outcome: a controls framework, an audit ready evidence pack, a board briefing, or a launch readiness review. I share a written proposal after the discovery call.

  • Yes, for clients who want ongoing access between engagements. Typically a fixed number of hours per month for advisory, review, and escalation support.

  • Always. NDAs are standard. I don't use client material in marketing without explicit, written permission.

Let's talk

Two ways in.

Book a free 30-minute discovery call to talk through your situation, or send a written inquiry and I'll reply within two business days.

Book a discovery call
Email
hello@builditsafe.ai
Response time
Within two business days